By the time a drive reaches us it usually holds the things somebody would least want read by a stranger. What follows is how that is handled in practice rather than a statement of intent — ICO registration, one named engineer per job, no subcontracting, and nothing crossing a border at any stage.
On the ICO register and GDPR-compliant. One named engineer per job, confidentiality assumed rather than negotiated, and working copies destroyed on a schedule you set rather than one we choose.
A good deal of UK data recovery is passed onward to a third party, which means more hands, more transit and more people with access. Ours is not.
Data does not leave the country at any point, which matters for regulated work and for anyone with contractual restrictions on where their information sits.
The same person throughout on business and institutional work, so the number of people with access is as small as it can be and is recorded.
Registered with the Information Commissioner's Office, with chain of custody documented as standard on regulated work whether or not it is requested.
We do not browse your files. Recovery verifies that files open and are structurally intact. It does not require reading them, and on encrypted material such as a cryptocurrency wallet we return the file without ever unlocking it.
We do not keep copies. Working images are destroyed after delivery. Original media is held 14 days in case something was missed, then securely wiped unless you have asked otherwise.
We do not ask for your keys. Passphrases, seed phrases and private keys are never needed to return you an encrypted file. Anyone asking for them is doing something other than recovery.
We do not bypass encryption on media you do not own. Where the requester is not the owner, we decline. That has cost us work and it remains the right answer.
NDAs, data processing agreements and information governance terms can all be signed before anything is sent rather than retrofitted afterwards. Tell us at the diagnostic what framework applies and it will be in place in advance.
For clinical, legal and financial work we document receipt, acquisition and every transfer as standard. Where a matter may end up in a proceeding, that record is the difference between findings that survive challenge and findings that do not — and it cannot be applied retrospectively.
Secure destruction with a certificate listing devices by serial number is available for equipment that is not coming back into service.
The engineer working on it, and on business work that is one named person throughout. Nothing is subcontracted and no data leaves the UK.
Working images are destroyed after delivery. Your original media is held 14 days in case anything was missed, then securely wiped unless you have asked otherwise.
Yes, and before the equipment arrives. We would rather work to your terms than insist on ours.
No. Everything happens at Vision Park and data does not leave the UK.
Not without the owner's authority. We decline requests to bypass encryption or access media where the requester is not the owner, and we will not make exceptions for a plausible story.
Available with a certificate listing each device by serial number and the method applied. Method follows media — overwriting works on disks, cryptographic erase on SSDs, physical destruction on flash and dead drives.